Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-11-30 CVE-2012-4220 Unspecified vulnerability in Google Android
diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.
network
google
6.8
2012-10-10 CVE-2012-3987 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
network
high complexity
mozilla google CWE-264
4.0
2012-09-28 CVE-2012-4017 Code Injection vulnerability in Jb+ Jigbrowser+ 1.0.5/1.5.0/1.5.5
The jigbrowser+ application before 1.5.0 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
network
google jb CWE-94
4.3
2012-09-28 CVE-2012-4016 Permissions, Privileges, and Access Controls vulnerability in Justsystems Atok
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.
4.3
2012-09-13 CVE-2012-4909 Information Exposure vulnerability in Google Chrome
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.
network
google CWE-200
4.3
2012-09-13 CVE-2012-4906 Permissions, Privileges, and Access Controls vulnerability in Google Chrome
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.
network
low complexity
google CWE-264
5.0
2012-09-13 CVE-2012-4905 Cross-Site Scripting vulnerability in Google Chrome
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."
network
google CWE-79
4.3
2012-09-13 CVE-2012-4904 Cross-Site Scripting vulnerability in Google Chrome
Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.
network
google CWE-79
4.3
2012-09-13 CVE-2012-4903 Permissions, Privileges, and Access Controls vulnerability in Google Chrome
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4906.
network
low complexity
google CWE-264
5.0
2012-08-31 CVE-2012-4171 Remote Denial of Service vulnerability in Adobe Flash Player and AIR
Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allow attackers to cause a denial of service (application crash) by leveraging a logic error during handling of Firefox dialogs.
network
low complexity
adobe google linux apple microsoft
5.0